Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2023-0999 A vulnerability classified as problematic was found in SourceCodester Sales Tracker Management System 1.0. This vulnerability affects unknown code of… Sales Tracker Management System No fix yet Fix from $1,9502023-02-24 HIGH 8.8 CVE-2022-1607 Cross-Site Request Forgery (CSRF) vulnerability in ABB Pulsar Plus System Controller NE843_S, ABB Infinity DC Power Plant allows Cross Site Request F… Infinity Dc Power Plant 5.0.0+ Fix from $1,9502023-02-24 HIGH 8.8 CVE-2023-20011 A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Network Controller… Application Policy Infrastructure Controller 5.2 / 6.0+ Fix from $1,9502023-02-23 HIGH 8.8 CVE-2023-0988 A vulnerability, which was classified as problematic, has been found in SourceCodester Online Pizza Ordering System 1.0. This issue affects some unkn… Online Pizza Ordering System No fix yet Fix from $1,9502023-02-23 HIGH 8.8 CVE-2023-24415 Cross-Site Request Forgery (CSRF) vulnerability in QuantumCloud AI ChatBot plugin <= 4.2.8 versions. Chatbot 4.2.9+ Fix from $1,9502023-02-23 HIGH 8.8 CVE-2023-23659 Cross-Site Request Forgery (CSRF) vulnerability in MainWP Matomo Extension <= 4.0.4 versions. Motomo 4.0.5+ Fix from $1,9502023-02-23 HIGH 8.8 CVE-2023-24384 Cross-Site Request Forgery (CSRF) vulnerability in WpDevArt Organization chart <= 1.4.4 versions. Organization Chart after 1.4.4 Fix from $1,9502023-02-23 HIGH 8.8 CVE-2015-10081 A vulnerability was found in arnoldle submitByMailPlugin 1.0b2.9 and classified as problematic. This issue affects some unknown processing of the fil… Submitbymailplugin Patch available Fix from $1,9502023-02-20 MEDIUM 5.7 CVE-2023-25569 Apollo is a configuration management system. Prior to version 2.1.0, a low-privileged user can create a special web page. If an authenticated portal … Apollo 2.1.0+ Fix from $1,6002023-02-20 MEDIUM 5.4 CVE-2023-24388 Cross-Site Request Forgery (CSRF) vulnerability in WpDevArt Booking calendar, Appointment Booking System plugin <= 3.2.3 versions affects plugin form… Booking Calendar 3.2.4+ Fix from $1,6002023-02-17 MEDIUM 6.5 CVE-2021-33396 Cross Site Request Forgery (CSRF) vulnerability in baijiacms 4.1.4, allows attackers to change the password or other information of an arbitrary acco… Baijiacms No fix yet Fix from $1,6002023-02-15 HIGH 8.8 CVE-2023-23465 Media CP Media Control Panel latest version. CSRF possible through unspecified endpoint. Media Control Panel No fix yet Fix from $1,9502023-02-15 HIGH 8.8 CVE-2023-25767 A cross-site request forgery (CSRF) vulnerability in Jenkins Azure Credentials Plugin 253.v887e0f9e898b and earlier allows attackers to connect to an… Azure Credentials 254.v64da_8176c83a+ Fix from $1,9502023-02-15 MEDIUM 6.1 CVE-2022-47373 Reflected Cross Site Scripting in Search Functionality of Module Library in Pandora FMS Console v766 and lower. This vulnerability arises on the forg… Pandora Fms after 766 Fix from $1,6002023-02-15 MEDIUM 5.4 CVE-2022-47372 Stored cross-site scripting vulnerability in the Create event section in Pandora FMS Console v766 and lower. An attacker typically exploits this vuln… Pandora Fms after 766 Fix from $1,6002023-02-15 HIGH 8.8 CVE-2022-29557 LexisNexis Firco Compliance Link 3.7 allows CSRF. Firco Compliance Link Mitigation only Fix from $1,9502023-02-15 HIGH 8.8 CVE-2022-46862 Cross-Site Request Forgery (CSRF) vulnerability in ExpressTech Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin <= 8.0… Quiz And Survey Master 8.0.8+ Fix from $1,9502023-02-14 HIGH 8.8 CVE-2023-24377 Cross-Site Request Forgery (CSRF) vulnerability in Ecwid Ecommerce Ecwid Ecommerce Shopping Cart plugin <= 6.11.3 versions. Ecwid Ecommerce Shopping Cart 6.11.4+ Fix from $1,9502023-02-14 HIGH 8.8 CVE-2023-24382 Cross-Site Request Forgery (CSRF) vulnerability in Photon WP Material Design Icons for Page Builders plugin <= 1.4.2 versions. Material Design Icons For Page Builders 1.4.3+ Fix from $1,9502023-02-14 HIGH 8.8 CVE-2023-25065 Cross-Site Request Forgery (CSRF) vulnerability in ShapedPlugin WP Tabs – Responsive Tabs Plugin for WordPress plugin <= 2.1.14 versions. Wp Tabs 2.1.15+ Fix from $1,9502023-02-14 HIGH 8.8 CVE-2022-43469 Cross-Site Request Forgery (CSRF) vulnerability in Orchestrated Corona Virus (COVID-19) Banner & Live Data plugin <= 1.7.0.6 versions. Corona Virus \(covid 19\) Banner \& Live Data after 1.7.0.6 Fix from $1,9502023-02-14 HIGH 8.8 CVE-2023-25066 Cross-Site Request Forgery (CSRF) vulnerability in FolioVision FV Flowplayer Video Player plugin <= 7.5.30.7212 versions. Fv Flowplayer Video Player after 7.5.30.7212 Fix from $1,9502023-02-14 HIGH 8.8 CVE-2023-22375 Cross-site request forgery (CSRF) vulnerability in Wired/Wireless LAN Pan/Tilt Network Camera CS-WMV02G all versions allows a remote unauthenticated … Cs Wmv02g Firmware Mitigation only Fix from $1,9502023-02-14 HIGH 8.1 CVE-2022-4138 A Cross Site Request Forgery issue has been discovered in GitLab CE/EE affecting all versions before 15.6.7, all versions starting from 15.7 before 1… GitLab 15.6.7 / 15.7.6+ Fix from $1,9502023-02-13 HIGH 8.8 CVE-2022-41134 Cross-Site Request Forgery (CSRF) in OptinlyHQ Optinly – Exit Intent, Newsletter Popups, Gamification & Opt-in Forms plugin <= 1.0.15 versions. Optinly 1.0.16+ Fix from $1,9502023-02-13 HIGH 8.8 CVE-2022-34448 PowerPath Management Appliance with versions 3.3 & 3.2*, 3.1 & 3.0* contains a Cross-site Request Forgery vulnerability. An unauthenticated non-privi… Powerpath Management Appliance Mitigation only Fix from $1,9502023-02-11 HIGH 8.8 CVE-2022-3568 The ImageMagick Engine plugin for WordPress is vulnerable to deserialization of untrusted input via the 'cli_path' parameter in versions up to, and i… Imagemagick Engine 1.7.6+ Fix from $1,9502023-02-10 HIGH 8.8 CVE-2022-41620 Cross-Site Request Forgery (CSRF) vulnerability in SeoSamba for WordPress Webmasters plugin <= 1.0.5 versions. Seosamba after 1.0.5 Fix from $1,9502023-02-08 MEDIUM 6.5 CVE-2023-0735 Cross-Site Request Forgery (CSRF) in GitHub repository wallabag/wallabag prior to 2.5.4. Wallabag 2.5.4+ Fix from $1,6002023-02-07 MEDIUM 5.4 CVE-2022-2933 The 0mk Shortener plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.2. This is due to missing or i… 0mk Shortener after 0.2 Fix from $1,6002023-02-06